PRELIMINARY ANALYSIS · FREE

What state is your external attack surface in?

CSURFACE runs a passive analysis on your domain, the way an adversary sees it from outside, and returns a report with a security grade, findings by severity, and how many of them are already under known exploitation. Nothing gets installed and it costs nothing.

WHERE ENUMERATION STOPS

Listing subdomains is the easy part

Any external surface tool returns a list of subdomains. The raw list does not say who owns each asset, which business unit depends on it, whether the flaw found is exploitable in the context it sits in, or which of those items someone is scanning the internet for right now.

That work is what separates a list from a remediation plan. CSURFACE attributes ownership for each asset, adds business context, validates whether the exposure is genuinely exploitable, and orders the queue by what is under observed attack. The preliminary analysis shows the aggregate result of that process; the platform shows it asset by asset.

WHAT YOU RECEIVE

The state of your surface, measured from outside

A 19-page report with the security grade of your external surface and the real size of what is exposed. Passive, non-intrusive, and free.

  • A 0–1000 security grade, with an A–F mark across ten posture domains: network, DNS, web application, TLS, vulnerabilities, data exposure, identity, supply chain, reputation, and email.
  • The size of what is exposed: how many domains, hosts, applications, and certificates discovery finds from your root domain.
  • Findings by severity, and how many are already under known exploitation, cross-referenced with CISA KEV, EPSS, and public exploit.
  • Email hygiene domain by domain: DMARC, SPF, and DNSSEC, these named per domain.
  • How many of your corporate credentials show up in known breaches.
  • One critical vulnerability in full detail, with impact and recommendation, as a sample of the platform's depth.

How it works

  • 1 · You fill in the data on the side. The analysis runs on your company's domain.
  • 2 · CSURFACE maps the external surface passively. No agents are installed; no systems are altered.
  • 3 · You receive the result by email.

What the preliminary analysis does not do: it does not list your assets one by one. It shows how many exist, what state they are in, and what is already being attacked. The named inventory, with owner, version, and business context per asset, is what the platform delivers. No credit card. The analysis only runs with your consent and declaration of ownership of the assets.

Request your free analysis

Response with the external perspective of your exposure.